隐私政策 / Privacy Policy
中文版本 · 如中英文版本存在歧义,以中文版本为准。生效日期:2026-09-28
一、适用范围
本政策适用于「KONLLEN AI 收藏家」(英文名称:KONLLEN AI Collector,Chrome 应用商店 Item ID:
fgfhpoffiabbaaoogijacpjgeabokoop,当前版本 2.3.4)Chrome 浏览器扩展(以下简称“本扩展”)。
本扩展由 南通康竺进出口贸易有限公司(以下简称“我们”)开发并运营,面向企业客户提供。
企业客户的管理员在其组织内为本扩展下发策略并进行设备登记;员工在知悉本政策并授权的前提下使用本扩展。
本扩展属于企业内部的 AI 使用管理工具。如果您是以员工身份使用本扩展,您的雇主(即企业客户)是相关数据的控制者, 我们依据企业客户的指令处理数据。
二、单一用途
本扩展只有一个用途:在企业员工知情并授权的前提下,通过企业钉钉完成身份验证与设备登记,采集并上报 ChatGPT 页面的使用事件,供企业 IT / 合规部门进行用量统计与合规审计。
我们不会将本扩展用于该单一用途之外的任何目的,也不会将所收集的数据用于其他用途。
三、我们收集的数据类别
本扩展仅收集以下三类数据:
| 数据类别 | 具体内容 | 收集目的 |
|---|---|---|
| 个人身份信息 | 姓名、邮箱 / 钉钉账号标识 | 确认使用人身份,将使用事件归属到已授权的员工,供企业核验与合规审计 |
| 用户活动 | AI 使用事件:访问次数、会话时长、时间戳 | 生成用量统计与合规审计记录 |
| 设备标识 | 随机生成的安装 UUID、设备名、浏览器 / 操作系统版本 | 完成设备登记、区分不同设备、同步设备状态 |
- 安装 UUID 由本扩展在您的设备上随机生成,它不是硬件指纹、机器码或操作系统序列号;卸载并重新安装后会重新生成。
- 我们不收集上述三类之外的任何数据。
四、我们明确不收集的数据
本扩展不收集、不保存、不上传下列任何数据:
- ChatGPT 对话内容、提示词、回答正文
- 网页浏览历史
- 位置信息
- 健康信息
- 财务与支付信息
- 个人通信内容
说明:本扩展只记录用量指标(访问次数、会话时长、时间戳)。这些指标在页面内计算,对话正文本身不会被保存,也不会被上传到任何服务器。
五、权限与用途
本扩展申请以下权限,且每项权限都仅用于实现上述单一用途:
| 权限 | 用途 |
|---|---|
storage | 在本机保存设备标识、登录凭证、企业下发的策略配置与待上报事件队列 |
alarms | 定时上报使用事件与同步设备状态 |
tabs | 判断当前标签页是否为需纳入统计的 AI 页面(如 chatgpt.com / chat.openai.com) |
declarativeNetRequest | 按企业管理员下发的策略,对特定域名请求做放行或拦截(例如限制访问未授权的 AI 站点) |
host permission(主机权限:<all_urls>) | 在指定 AI 服务页面(如 chatgpt.com / chat.openai.com)注入内容脚本、与企业内部管理端通信;除企业策略要求外不访问其他站点 |
除企业策略要求外,本扩展不访问其他站点;也不会将这些权限用于与上述用途无关的行为,或读取与 AI 使用统计无关的页面内容。
六、数据的上报与共享
- 数据仅上报至企业自建的管理端(即企业管理员配置的内部管理服务),用于企业自身的用量统计与合规审计。
- 我们不向任何第三方出售、出租或转让这些数据。
- 我们不将数据用于广告投放、用户画像或个性化推荐。
- 我们不将数据用于信用评估、放贷或其他金融用途。
- 数据通过 HTTPS / TLS 加密传输;管理端的访问权限由企业按最小必要原则控制。
- 企业管理员可在管理端后台配置策略,包括启用范围、采集项与数据保留期限。
七、数据保留期限与删除方式
- 保留期限:由企业管理员在管理端配置的策略决定,当前默认保留期限为 180 天;超出保留期限的数据将被删除或匿名化。
- 员工申请查看或删除:员工可随时联系所在企业的管理员,申请查阅、更正或删除与其相关的数据;我们将在企业客户的指令下配合处理。
- 卸载即清除本机数据:卸载本扩展后,保存在浏览器本机的数据(设备标识、登录凭证、策略配置与待上报事件队列)将随扩展一并清除。
- 已上报至企业管理端的数据,由企业按其内部制度与适用法律删除。
八、数据安全措施
- 传输加密:所有上报数据均通过 HTTPS / TLS 加密通道传输。
- 访问控制:仅经企业授权的管理员可访问管理端数据。
- 最小必要:仅采集实现单一用途所必需的最少数据,不采集对话正文与浏览历史。
- 本机最小化存储:本机仅保存设备标识、登录凭证、策略配置与待上报事件队列。
九、政策变更通知
本政策如有更新,我们会在本页面发布最新版本,并同步更新“最近修订”日期。若变更涉及数据类别、使用目的或共享方式的重大调整, 我们将通过企业管理员向员工通知。在变更生效后继续使用本扩展,即表示您接受更新后的政策。
十、联系方式
- 开发者 / 运营主体:南通康竺进出口贸易有限公司
- 纳税人识别号:91320621MA1WRWW30U
- 隐私事务联系邮箱:1715676356@qq.com
- 通信地址:南通市海安市海安镇民建路28号101室
员工如希望行使查阅、更正或删除等数据权利,也可直接联系所在企业的 IT / 合规管理员。
十一、适用法律
本政策适用中华人民共和国法律。因本政策产生的争议,双方应友好协商解决;协商不成的,提交有管辖权的人民法院裁决。
隐私政策 / Privacy Policy
English version · In case of any discrepancy between the Chinese and English versions, the Chinese version prevails. Effective date: 2026-09-28
1. Scope
This Policy applies to the “KONLLEN AI Collector” Chrome browser extension (Chinese name: KONLLEN AI 收藏家;
Chrome Web Store item ID fgfhpoffiabbaaoogijacpjgeabokoop; current version 2.3.4), referred to below as
“the Extension”. The Extension is developed and operated by
南通康竺进出口贸易有限公司 (“we”, “us”), and is provided to enterprise customers.
Administrators of the enterprise customer deploy policies and register devices within their organization;
employees use the Extension after being informed of this Policy and giving their authorization.
The Extension is an internal enterprise tool for managing AI usage. If you use the Extension as an employee, your employer (the enterprise customer) is the controller of the relevant data, and we process data on the instructions of that enterprise customer.
2. Single Purpose
The Extension has one single purpose: with the knowledge and authorization of enterprise employees, to verify identity and register devices through enterprise DingTalk, and to collect and report ChatGPT usage events so that the enterprise IT / compliance function can perform usage statistics and compliance auditing.
We do not use the Extension for any purpose beyond this single purpose, and we do not use the collected data for any other purpose.
3. Data We Collect
The Extension collects only the following three categories of data:
| Category | What it includes | Why we collect it |
|---|---|---|
| Personally identifiable information | Name; email address / DingTalk account identifier | To identify the user, attribute usage events to an authorized employee, and support enterprise verification and compliance auditing |
| User activity | AI usage events: number of visits, session duration, timestamps | To produce usage statistics and compliance audit records |
| Device identifiers | Randomly generated installation UUID, device name, browser / operating system version | To perform device registration, distinguish devices, and synchronize device status |
- The installation UUID is randomly generated on your device by the Extension. It is not a hardware fingerprint, machine code, or operating system serial number, and it is regenerated if the Extension is uninstalled and reinstalled.
- We do not collect any data outside the three categories listed above.
4. Data We Do Not Collect
The Extension does not collect, store, or transmit any of the following:
- ChatGPT conversation content, prompts, or response text
- Web browsing history
- Location information
- Health information
- Financial and payment information
- Personal communications content
Note: the Extension records usage metrics only (number of visits, session duration, and timestamps). These metrics are computed within the page; conversation text itself is neither stored nor uploaded to any server.
5. Permissions and Their Purpose
The Extension requests the following permissions, each used solely to fulfil the single purpose described above:
| Permission | Purpose |
|---|---|
storage | To store the device identifier, sign-in credential, enterprise-delivered policy configuration, and the pending event upload queue locally on your device |
alarms | To periodically report usage events and synchronize device status |
tabs | To determine whether the current tab is an AI page to be included in usage statistics, such as chatgpt.com or chat.openai.com |
declarativeNetRequest | To allow or block requests to specific domains under administrator-delivered enterprise policy, such as restricting access to unauthorized AI sites |
host permission (<all_urls>) | To inject the content script on designated AI service pages, such as chatgpt.com or chat.openai.com, and communicate with the enterprise’s internal management endpoint; except as required by enterprise policy, the Extension does not access other sites |
Except as required by enterprise policy, the Extension does not access other sites. It also does not use these permissions for anything unrelated to the purposes above or read page content unrelated to AI usage statistics.
6. How Data Is Reported and Shared
- Data is reported only to the enterprise’s self-hosted management endpoint (the internal management service configured by the enterprise administrator), for the enterprise’s own usage statistics and compliance auditing.
- We do not sell, rent, or transfer this data to any third party.
- We do not use this data for advertising, user profiling, or personalized recommendations.
- We do not use this data for credit assessment, lending, or any other financial purpose.
- Data is transmitted over HTTPS / TLS; access to the management endpoint is controlled by the enterprise on a least-privilege basis.
- Enterprise administrators can configure policies in the management console, including the scope of enablement, collected items, and data retention period.
7. Data Retention and Deletion
- Retention period: determined by the policy configured by the enterprise administrator in the management console. The current default retention period is 180 days; data beyond the retention period is deleted or anonymized.
- Requests to access or delete: employees may contact their enterprise administrator at any time to request access to, correction of, or deletion of their related data. We will assist in handling such requests under the instructions of the enterprise customer.
- Local data is cleared on uninstall: when the Extension is uninstalled, the data stored locally in the browser (device identifier, sign-in credential, policy configuration, and the pending event upload queue) is removed together with the Extension.
- Data already reported to the enterprise management endpoint is deleted by the enterprise in accordance with its internal rules and applicable law.
8. Data Security Measures
- Encryption in transit: all reported data is transmitted over HTTPS / TLS.
- Access control: only administrators authorized by the enterprise may access management-end data.
- Data minimization: only the minimum data required for the single purpose is collected; conversation text and browsing history are never collected.
- Minimal local storage: only the device identifier, sign-in credential, policy configuration, and pending event upload queue are stored locally.
9. Changes to This Policy
If this Policy is updated, we will publish the latest version on this page and update the “Last revised” date accordingly. If a change materially affects the categories of data, the purposes of use, or the way data is shared, we will notify employees through enterprise administrators. Continuing to use the Extension after a change takes effect constitutes acceptance of the updated Policy.
10. Contact Us
- Developer / operating entity: 南通康竺进出口贸易有限公司
- Taxpayer identification number: 91320621MA1WRWW30U
- Privacy contact email: 1715676356@qq.com
- Postal address: 南通市海安市海安镇民建路28号101室
Employees who wish to exercise data rights such as access, correction, or deletion may also contact their enterprise’s IT / compliance administrator directly.
11. Governing Law
This Policy is governed by the laws of the People’s Republic of China. Any dispute arising from this Policy shall be resolved through friendly negotiation; if negotiation fails, the dispute shall be submitted to a competent people’s court.